Alerting

Alert when Avg duration greater than threshold

sivaranjani
Explorer

I have a query that displays avg duration. How to i modify query to alert if avg ( duration) is greater than 1000 last 15 mins. 

index=tra cf_space_name="pr" "cf_app_name":"Sch" "msg"."Logging Duration" AND NOT "DistributedLockProcessor" |rename msg.DurationMs as TimeT |table _time TimeT msg.Service
| bucket _time span=1m
| stats
avg(TimeT) as "Avg"
by msg.Service

11.JPG

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Use your search in an alert and add the following

| where Avg > 1000

Then set the timeframe for the search to be last 15 minutes and the alert trigger to be when there are greater than zero results

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...